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1 . (Original) In a distributed network having a number of server computers and 
associated client devices, method of isolating infected client devices from uninfected client 
devices, comprising: 

correlating network related virus infection information; 

determining if a virus outbreak has occurred based on the correlated information; 
isolating infected client devices from uninfected client devices when the virus outbreak is 
confirmed; 

monitoring ail data packets in the network for the virus; 
identifying a packet type associated with the virus; and 
blocking only the identified packet type. 

2. (Canceled) 

3. (Currently Amended) A method as recited in claim 2, further 
comprising: 

forwarding to a v irus/worm virus analyzer unit coupled to the network 
computer v irus/worft * virus sensor only those data packets deemed to be infected 
by the identified computer virus or computer worm a*e. 



4. . (Currently Amended) A method as recited in claim 3, wherein in 
the first mode, copying by the traffic controller substantially all data packets 
included in the network traffic; and 
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forwarding the copied data packets to the v4^frA*ere virus analyzer unit. 

5. (Currently Amended) A method as recited in claim 4, comprising: 
forwarding the copied data packet to a packet protocol determinator; and 
determining *f the packet protocol of the copied data packet i^ enc MUoly to 

b o inf o o t od by the dotoot c ri ro m p iu o r vi*us or computer worm , 

6. (Currently Amended) A method as recited in claim 5 9 further 
comprising: 

receiving at a trash collector those copied dala packets determined io be of a 
first set of one or more specific a: protocols not likely to be - infect e d b y-**re- 
dfr taotod oomputor vhua or computer worm ; and 

receiving and analyzing those copied data packets determined to be of a- one 
or more snccific proiocol W ccly to b o infectc d- by the detected c o mputer virus or 
eOTftp atcr worm at a fllescan unit. 

7. (Currently Amended) A method as recited in claim 6, further 
comprising: 

determining by a v4-mAv^ffl virus analyzer unit if those copied data packets 
received at the filescan unit are infected by the detected computer virus or 
computer worm; 

forwarding those packets determined not to be infected to the trash collector; 

analyzing the infected copied data packets; and 

generating a virus report based upon the analysis. 
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8. (Original) In a distributed network having a number of server computers and 
associated client devices, computer program product for isolating infected client devices from 
uninfected client devices, comprising: 

computer code for correlating network related virus infection information; 

determining if a virus outbreak has occurred based on the correlated information; 

computer code for isolating infected client devices from uninfected client devices when 
the virus outbreak is confirmed; 

computer code for monitoring all data packets in the network tor the virus; 

computer code for identifying a packet type associated with the virus; 

computer code for blocking only the identified packet type; and 

computer readable medium for storing the code. 

9. (Canceled) 

10. (Currently Amended) Computer program product as recited in 

claim 9, further comprising: 

computer code for forwarding to a v i rus/worm virus a nalyzer unit coupled 
the network computer virus/worm sensor only those data packets deemed to be 
infected by the identified computer virus or computer worm are. 

1 1 . (Currently Amended) Computer program product as recited in 
claim 10, wherein in the first mode, copying by the traffic controller 
substantially all data packets included in the network traffic; and 

computer code for forwarding the copied data packets to the viru o /worm 
virus analyzer unit. 
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12. (Currently Amended) Computer program product as recited in 

claim 11, comprising: 

computer code for forwarding the copied data packet to a packet protocol 

dcterminator; and 

computer code tor determining if the packet protocol of the copied data 
packet twti kly to bo infected by the doHM rted-ooi nputm , - irua or en m p nter 
worm . 

13. (Currently Amended) Computer program product as recited in 

claim 12, further comprising: 

computer code for receiving at a trash collector those copied data packets 
determined to be of a * «~* set of one «r more sne.ific protocols not likely to b e 
iii fcct od by t^Hi r ' Tn^tnH mmpntor virus oi cui nputor worm ; and 

computer code for receiving and analyzing those copied data packets 
determined to be of a second set (if "™ more specific protocols likely to be 
iefegted-by- th o detected computer virus or comput»r^ w» at a filcscan unit. 

14. (Currently Amended) Computer program product as recited in 

claim 13, further comprising: 

computer code for determining by a v4*»sAvo«n y_irus_analyzer unit if those 
copied data packets received at the filcscan unit are infected by the detected 
computer virus or computer worm; 

computer code for forwarding those packets determined not to be infected to 

the trash collector; 
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computer code for analyzing the infected copied dam packets; and 
computer code for generating a virus report based upon the analysis. 
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